5.3
CVE-2024-28067
- EPSS 0.55%
- Veröffentlicht 09.07.2024 18:15:09
- Zuletzt bearbeitet 21.11.2024 09:05:44
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
A vulnerability in Samsung Exynos Modem 5300 allows a Man-in-the-Middle (MITM) attacker to downgrade the security mode of packets going to the victim, enabling the attacker to send messages to the victim in plaintext.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Samsung ≫ Exynos Modem 5300 Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.55% | 0.672 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.7 | 2.2 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
|
| cve@mitre.org | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.